Security1 distinct publisher3 min readPublished
South Korea's cyber agency published a free tool that recovers Rhysida-encrypted Windows files. Emsisoft says three other parties had the same flaw first and kept quiet about it.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The weakness is in key generation, not in the cipher. Rhysida's random number generator draws on data from the machine it runs on, and the Kookmin University and KISA researchers showed that machine state can be reconstructed after the fact, which yields the number, which yields the key [4][5]. Nothing about the gang's encryption has to change to close that off. Only the source of its keys does, which is why the newsletter's expectation is a patch, and why it notes that none of these bugs has survived publication [11].
The finder count is the part worth dwelling on. Emsisoft CTO Fabian Wosar says Avast had the flaw in October of the previous year, a French CERT paper on it circulated privately in June, and he found it himself in May of the previous year [8]. Add the team that published, and one weakness in one PRNG was independently discovered by at least four separate parties [15]. The argument for silence assumes the secret holds. A bug that four groups walked into inside roughly the same nine-month window [17] was already on a clock, and the only question was whose disclosure stopped it.
Then the volumes, which cut the other way. Wosar says Emsisoft decrypted hundreds of systems using the flaw [9]. Over the nine months it stayed quiet, Rhysida encrypted files at more than 80 victims [13], about nine a month [16]. Systems are not organisations, so hundreds of machines spread across 80-odd victim networks is entirely plausible, and that is the strongest thing anyone in this story has said for private circulation. It sits awkwardly beside the same newsletter's own verdict that these decryption bugs may not have the biggest impact even when kept secret [14].
What private circulation cannot do is reach a victim who is not already in the pipeline. The tools get handed to law enforcement, national CERTs and cyber agencies, who pass them to victims after an attack [7]. That works for organisations that report, in countries with a functioning CERT, or that have a relationship with the right vendor. A published tool on a government website does not check any of that, which is the actual trade being argued over: help everyone once, or help the reporting subset for as long as the flaw lasts [6].
The group has form here. Nearly the same team published a free decrypter and paper for Hive in June 2022; the FBI infiltrated Hive a month later and dismantled the operation in January 2023, and the two events were unrelated [10]. So the publication record is not a takedown record, and nobody should treat it as one. What is missing from both sides of this argument is the number that would settle it: how many victims each route actually recovered. Emsisoft gave a figure for its own channel [9]. Nobody publishes the denominator.
Ranked by verification strength, evidence, and original report placement.
Emsisoft CTO Fabian Wosar said the Rhysida flaw was independently found by at least three other parties who circulated it privately: Avast found it in October of the previous year, the French CERT authored a private paper on it in June, and Wosar found it in May of the previous year.
South Korean researchers cracked the encryption scheme used by the Rhysida ransomware and released a decrypter, available through the website of South Korea's cybersecurity agency KISA, that allows victims to recover files without paying the ransom.
The decrypter is based on a white paper published by academics from Kookmin University and members of KISA.
The decryption tool works only for Windows systems and exploits a weakness in the ransomware's cryptographically secure pseudo-random number generator (CSPRNG).
Rhysida's CSPRNG takes data from a local PC to generate a random number that is then used to create the encryption key the ransomware uses on a victim's files.
Kookmin and KISA researchers found they could determine a system's state at the time the CSPRNG generated the random number, meaning they could infer the encryption key.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Concrete mechanism, single-outlet sourcing
The cryptographic mechanism is described specifically (CSPRNG seeded from local system state, state reconstruction yielding the key) and is anchored to a named published white paper plus a named, quoted industry source. But everything comes from one newsletter with no second publisher, no primary link-through verification of the Avast or French CERT discovery dates, and no independent check on the decryption volume claimed.
Tool shipped and reportedly used at scale privately
Adoption is real but asymmetric: the public decrypter is shipped and downloadable from a national agency, and the private version of the same flaw was reportedly used to decrypt hundreds of systems. What is missing is any measure of uptake of the KISA tool itself — no download, victim-recovery or CERT-distribution figures — and the 80-plus continuing victims show the flaw did not blunt Rhysida's operations.
Slightly overstated durability, self-tempered
The headline capability — a working free decrypter — is genuine, but its practical value is likely short-lived: the publisher itself expects Rhysida to patch within weeks, consistent with the community norm that binary-flaw decrypters get closed once published, and the tool's scope is Windows-only. That gap is small because the same article supplies the caveats, explicitly argues the release may have destroyed a private recovery route, and concludes such bugs 'may not have the biggest impact.'
Vendor and agency interests both in play
The core counter-narrative comes from a vendor CTO whose firm monetizes incident response and whose private decryption capability is devalued by publication, so 'we decrypted hundreds of systems' is both a factual claim and a positioning statement. On the other side, a national agency and university authors gain visibility from publishing rather than routing the flaw through the private firm-to-CERT channel the same article describes as standard. The newsletter also carries a named sponsor, disclosed at the top of the issue.
Credible but single-publisher and partly forward-looking
Confidence is moderate: the central facts are specific and attributed, and the publisher is a specialist security outlet. It is held down by the absence of any second publisher, reliance on one on-record quote for the multi-party discovery narrative, unverified decryption volumes, and a key element — whether Rhysida patches the bug — that the article states as an explicit prediction rather than an observation.
security
FBI counts 30-plus ransomware disruptions this year, and the target is the plumbing1 distinct publisher
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
security
Nitrogen's ESXi encryptor is broken, which means the ransom buys nothing1 distinct publisher
leadership
VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026